← All articles
indian law firm whatsapp automation bar council of india rule 36 advertising ban By BossBot Editorial Team · · 22 min read
Drafted with AI assistance under founder-led editorial direction. How our editorial team works.

Indian Law Firms: The Bar Council Rule 36 WhatsApp Reckoning

People sitting near table with laptop computer
Photo: Campaign Creators · Unsplash

Bar Council of India Rule 36 bans advertising by advocates. What that means for any Indian law firm building WhatsApp client-comms in 2026.

In this article Hide ▲
  1. Bar Council of India Rule 36 — the sentence-by-sentence reading
  2. DPDPA 2023 and the Data Protection Board — what changed August 2025
  3. Advocate-client privilege — why the panel choice matters legally
  4. IT Rules 2021 + 2023 — the intermediary layer
  5. Payment layer — GST reverse charge, UPI, and why WhatsApp Pay India is not for firms
  6. The Indian legal market realities — what WhatsApp vendors don't factor
  7. The WhatsApp automation stack that actually fits Rule 36 + DPDPA

Bar Council of India Rule 36 — the sentence-by-sentence reading

Rule 36 of the BCI Rules of Professional Conduct and Etiquette (part of Chapter II Section IV, framed under Section 49(1)(c) of the Advocates Act 1961) reads in substance: "An advocate shall not solicit work or advertise, either directly or indirectly, whether by circulars, advertisements, touts, personal communications, interviews not warranted by personal relations, furnishing or inspiring newspaper comments or producing his photograph to be published in connection with cases in which he has been engaged or concerned."

The 2008 amendment (post the Bombay High Court judgement in V.B. Joshi vs Union of India) inserted a narrow exception permitting an advocate to furnish website particulars: name, address, telephone, email, enrolment number, date of enrolment, name of state Bar Council on which enrolled, professional and academic qualifications, and areas of practice — subject to the particulars being furnished to the Bar Council of India, and subject to the advocate not soliciting work.

What Rule 36 means operationally for WhatsApp:

(a) An advocate cannot broadcast promotional messages to a purchased list of contacts saying "consult us for property disputes" or "free 15-minute consultation".

(b) An advocate cannot run WhatsApp Business marketing template messages (as Meta classifies them — marketing category) to recipients who have not first contacted the firm.

(c) An advocate cannot use missed-call to WhatsApp campaigns or outbound cold sequences.

(d) An advocate cannot publish before/after case-outcome content on WhatsApp Status connected with clients he has represented.

(e) An advocate cannot maintain testimonial-collection flows asking clients to send WhatsApp reviews for public reuse.

What Rule 36 permits:

(a) Answering an incoming enquiry from a prospect who has obtained the firm's WhatsApp number from the firm's own Bar-Council-permitted website listing or from a directory.

(b) Transactional messages to existing clients — hearing reminders, document requests, court order updates, invoice, receipt.

(c) Passive listing of the firm's WhatsApp Business number on the firm's website alongside the other permitted particulars.

State Bar Councils enforce Rule 36 through disciplinary proceedings under Sections 35-38 of the Advocates Act 1961. Complaints from members of the public, from rival advocates, or suo motu by the Bar Council are routine — Rule 36 is not a paper tiger.

DPDPA 2023 and the Data Protection Board — what changed August 2025

The Digital Personal Data Protection Act 2023 (Act No. 22 of 2023), notified in the Gazette on 11 August 2023, entered phased enforcement from August 2025 onward under the Draft DPDP Rules 2025 notified in January 2025 by the Ministry of Electronics and Information Technology. The Data Protection Board of India (Section 18) is the enforcement body.

Key sections that hit an advocate operating a WhatsApp panel:

Section 4-6 — Grounds for processing. Consent (Section 6) is the primary ground. Consent must be free, specific, informed, unconditional, and unambiguous, given by clear affirmative action, and signifying agreement to processing of personal data for the specified purpose. Consent notices (Section 5) must be written in clear and plain language, in English or any language specified in the Eighth Schedule of the Constitution.

Section 7 — Legitimate uses. Includes voluntary provision for a specified purpose, employment, medical emergency, specified state functions. Legal services do not automatically fall under legitimate use — consent under Section 6 remains the default.

Section 8 — Data fiduciary obligations. Reasonable security safeguards (Section 8(5)), notification of personal data breach to Board and affected data principals (Section 8(6)), erasure on withdrawal of consent (Section 8(7)).

Section 9 — Children. Verifiable consent of parent required for data of children under 18. Advocates handling matrimonial or juvenile matters must implement this.

Section 33 — Penalties. Up to ₹250 crore (~US$30 million) for failure to take reasonable security safeguards preventing personal data breach. Up to ₹200 crore for failure to notify the Board of breach. Up to ₹150 crore for children's data violations.

Section 8 & 9 — Data Processing Agreement. A data fiduciary (the law firm) engaging a data processor (WhatsApp BSP, SaaS vendor) remains responsible for compliance. A written contract matching Section 8 is mandatory.

The DPDPA sits alongside Rule 36, not in its place. A law firm's WhatsApp deployment must clear both: Rule 36 (no solicitation) and DPDPA (consent, security, breach notification, processor contract).

🎯 For law firms
Weekly notes on what's actually working for law firms.
After-hours intake scripts, client-portal comparisons, retainer follow-ups — no fluff.

Advocate-client privilege — why the panel choice matters legally

Indian Evidence Act 1872, Sections 126-129 codifies advocate-client privilege:

Section 126 — No barrister, attorney, pleader or vakil shall at any time be permitted, unless with his client's express consent, to disclose any communication made to him in the course and for the purpose of his employment as such barrister, pleader, attorney or vakil, by or on behalf of his client, or to state the contents or condition of any document with which he has become acquainted in the course and for the purpose of his professional employment, or to disclose any advice given by him to his client in the course and for the purpose of such employment.

Section 127 — extends the privilege to interpreters, clerks and servants of the advocate.

Section 128 — client may waive.

Section 129 — no one may be compelled to disclose a confidential communication with a legal adviser.

Where WhatsApp panels break the privilege chain:

(a) Client sends a case document via WhatsApp to the firm's shared inbox on the panel. The document sits on the panel vendor's servers (typically US or EU cloud, sometimes India region for major vendors). If the vendor's staff can access the document without the client's consent, the privilege chain is at risk.

(b) A subpoena or a data breach forces disclosure. A firm that cannot demonstrate technical controls preventing vendor access faces a Section 126 challenge.

(c) Cross-border cloud storage without DPDPA-compliant contract (Section 16 on cross-border transfer once notified) adds a second exposure layer.

Practical mitigation:

• DPA (Data Processing Agreement) with the panel vendor explicitly acknowledging the material is legally privileged, with vendor-side access restrictions.

• Encryption at rest and in transit that even the vendor cannot decrypt without customer key.

• India-region data residency where the vendor offers it (AWS Mumbai, Azure India Central).

• Immediate handoff of substantive case documents from the WhatsApp panel to the firm's internal document management system (iManage, NetDocuments, or DMS-lite) — WhatsApp is the notification channel, not the storage of record.

Prohibition on shared numbers. A firm's WhatsApp Business number that receives messages for advocate A and advocate B in the same panel inbox risks unintended intra-firm disclosure of privileged material. Segregation by matter or by advocate handling is required.

IT Rules 2021 + 2023 — the intermediary layer

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended by IT Rules 2023 notified in April 2023, sit at the intermediary layer. A law firm operating its own WhatsApp panel is not itself an intermediary, but it is a user of intermediary services (WhatsApp, the BSP, the SaaS panel) and shares specific obligations:

Rule 3(1)(b) — the intermediary shall inform its users not to host or publish information that violates any law. Bulk solicitation messages sent through a WhatsApp automation panel would violate Rule 36 and could trigger the intermediary's obligation to disable access under Rule 3(1)(d).

Rule 4 — significant social media intermediaries — WhatsApp is a significant social media intermediary (over 5 million users in India, per Rule 2(w)) and is subject to enhanced obligations: Chief Compliance Officer, Nodal Contact Person, Grievance Officer, monthly compliance report. This affects how quickly a complaint about a law firm's WhatsApp broadcast will be escalated to the firm.

Rule 3(1)(j) — Grievance Redressal — the intermediary must acknowledge complaints within 24 hours and resolve within 15 days. A user (or a rival advocate, or a Bar Council member) reporting a firm for Rule-36-violating WhatsApp behaviour gets a 24-hour response window from Meta.

IT Rules 2023 amendment — fact-check unit — content flagged as false or misleading in respect of Government business must be taken down. A firm publishing WhatsApp content about government-litigation outcomes must avoid misrepresentation.

Interaction with DPDPA. DPDPA 2023 supersedes conflicting provisions in the IT Act 2000 Section 43A and the SPDI Rules 2011 for personal data protection specifically. IT Rules 2021 continue for intermediary conduct.

Payment layer — GST reverse charge, UPI, and why WhatsApp Pay India is not for firms

CGST Notification 13/2017 dated 28 June 2017, Entry 2, specifies that services supplied by an individual advocate including a senior advocate or firm of advocates by way of legal services, directly or indirectly, to any business entity located in the taxable territory are covered under Reverse Charge Mechanism (RCM). The recipient business entity is liable to pay GST, not the advocate. Legal services to non-business individuals are exempt under Notification 12/2017 Entry 45.

Practical implication for WhatsApp payment flow:

• The invoice sent through the WhatsApp panel must clearly state RCM applicability where the recipient is a business entity. The advocate does not collect GST on the invoice — the business client pays it directly under RCM.

• The advocate does still need GST registration if turnover crosses the threshold (currently ₹20 lakh for services in most states, ₹10 lakh in special-category states), even though the tax is paid by the recipient under RCM.

UPI (Unified Payments Interface) via NPCI is the dominant digital payment rail in India — the NPCI reports UPI processing tens of billions of transactions monthly, with UPI accounting for the large majority of digital retail payment volume. For a law firm, a UPI QR code or UPI ID shared via WhatsApp for client invoice payment is standard practice. Common apps: PhonePe, Google Pay, Paytm, BHIM, Amazon Pay.

WhatsApp Pay India — launched 2020 with NPCI approval — is a consumer-to-consumer and consumer-to-merchant offering with specific onboarding requirements. Most law firms use a UPI ID or UPI QR shared as a WhatsApp message rather than in-chat WhatsApp Pay merchant flow, both because merchant onboarding is separate and because the invoice/RCM/GST paper trail lives in the accounting system, not in WhatsApp.

Cards and international clients — Razorpay, PayU India, CCAvenue for card acceptance; Stripe is available in India for eligible businesses. Cross-border legal services fee receipts require Foreign Inward Remittance Certificate (FIRC) from the receiving bank.

The WhatsApp automation stack that actually fits Rule 36 + DPDPA

For a solo advocate or small firm — the minimal viable stack:

One WhatsApp Business Platform number (via a BSP — AiSensi, Interakt, DoubleTick, Gupshup India, Karix, Route Mobile), listed on the firm's Bar-Council-compliant website with the permitted particulars (name, address, phone, email, enrolment).

Inbound-only automation — a welcome auto-reply routing queries by matter type (civil, criminal, family, corporate), capturing basic details, logging consent per DPDPA Section 6, and handing off to the advocate. No outbound broadcast, no drip sequences to non-clients.

Transactional templates for existing clients only — hearing reminders, document requests, invoice notifications. Meta template category = utility, not marketing. Consent from the client on file.

UPI QR / UPI ID shared as needed for invoice payment. Invoice generated in the accounting software (Zoho Books, Tally, ClearTax, Vyapar), sent as PDF attachment. RCM disclosure clear on invoices to business clients.

Data Processing Agreement signed with the BSP and the SaaS panel vendor, matching DPDPA Section 8, acknowledging the potentially privileged nature of communications.

India data residency where offered — AiSensi, Interakt, DoubleTick, Gupshup all offer India-region hosting.

For a tier-1 or full-service firm — additional layers:

• Segregation of WhatsApp inboxes by matter or by partner to protect privilege chain.

• Immediate handoff of substantive documents from WhatsApp to the firm's DMS (iManage, NetDocuments) with retention rules.

• Named Grievance Officer under IT Rules 2021 Rule 3(2) if the firm operates a client-facing digital service beyond WhatsApp.

• Named Chief Compliance Officer under DPDPA Section 10 if the firm is notified as a Significant Data Fiduciary.

Panels that fit — realistic assessment:

Indian BSPs (AiSensi, Interakt, DoubleTick, Gupshup, Karix) — India data residency, INR billing, Hindi/regional-language support, familiarity with Indian compliance. Best fit for domestic-only firms.

International SaaS with India presenceWati (Hong Kong, widely used in India), Kommo (US), Sleekflow (Singapore/HK), BossBot — need explicit DPA + India data residency check.

What to avoid — any vendor selling "WhatsApp broadcast to 10,000 leads" or "cold outreach automation" as flagship features. These features exist for non-regulated verticals (e-commerce, D2C, coaching) and are precisely what Rule 36 prohibits for advocates.

Sources

Data + numbers referenced in this article are sourced from these public documents:

  1. Bar Council of India — Rules of Professional Conduct and Etiquette (Chapter II Section IV)
  2. Bar Council of India — Home
  3. The Advocates Act 1961 (Act No. 25 of 1961)
  4. Digital Personal Data Protection Act 2023
  5. DPDP Act 2023 — full text (Gazette of India)
  6. Draft Digital Personal Data Protection Rules 2025
  7. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021
  8. Indian Evidence Act 1872 — Sections 126-129 (Advocate-Client Privilege)
  9. CGST Notification 13/2017 — Reverse Charge Mechanism on Legal Services
  10. CGST Notification 12/2017 — Exempt Services (Entry 45 — legal services to non-business)
  11. V.B. Joshi vs Union of India — Bombay High Court WP 1085/2001
  12. National Payments Corporation of India (NPCI) — UPI Product Statistics
  13. WhatsApp Business Platform Pricing
  14. Bar Council of India Notification — Rules for Registration of Foreign Lawyers and Foreign Law Firms in India 2022
  15. Society of Indian Law Firms (SILF)

Frequently Asked Questions

No. Bar Council of India Rule 36, framed under Section 49(1)(c) of the Advocates Act 1961, prohibits an advocate from soliciting work or advertising directly or indirectly. Promotional WhatsApp broadcasts, drip campaigns to non-clients, missed-call promotional flows and case-outcome status content all fall within the prohibition. The 2008 amendment (post V.B. Joshi vs UOI) permits only passive website listing of name/address/qualifications/practice-areas. Enforcement is through State Bar Council disciplinary proceedings under Sections 35-38 of the Advocates Act.
Yes. The Digital Personal Data Protection Act 2023, entering phased enforcement from August 2025 under the Data Protection Board of India, applies to any data fiduciary processing personal data of data principals within India. A law firm collecting client contact details, case facts, or documents via WhatsApp is a data fiduciary. Consent under Section 6, security safeguards under Section 8(5), breach notification under Section 8(6), and Data Processing Agreements with BSP and SaaS vendors are all required. Penalties reach ₹250 crore for security failures.
No platform is inherently "safe" — privilege under Indian Evidence Act Sections 126-129 depends on operational controls. Look for: (a) DPA acknowledging the privileged nature of communications; (b) India data residency (AiSensi, Interakt, DoubleTick, Gupshup, Karix offer this natively; Wati and international vendors need explicit check); (c) encryption at rest with customer-managed keys; (d) immediate handoff of substantive documents to the firm's DMS rather than long-term WhatsApp storage; (e) inbox segregation by matter or partner to prevent unintended intra-firm disclosure.
Most Indian law firms use a UPI QR code or UPI ID shared via WhatsApp for client payments rather than WhatsApp Pay India's merchant flow. Reasons: (a) UPI accounts for the majority of Indian digital payments via PhonePe/Google Pay/Paytm/BHIM; (b) invoice + RCM + GST paper trail lives in the accounting system (Zoho Books, Tally, ClearTax) rather than in WhatsApp; (c) WhatsApp Pay merchant onboarding is a separate process. Legal services to business clients fall under CGST RCM per Notification 13/2017 — the client pays GST, not the advocate.
Safe under Rule 36 + DPDPA: (1) a listed WhatsApp Business number on the firm's Bar-Council-compliant website; (2) inbound-only auto-reply capturing enquiries with clear consent and routing by matter type; (3) transactional utility-category templates to *existing* clients — hearing reminders, document requests, invoices; (4) UPI QR/ID sharing for invoice payment; (5) immediate handoff of substantive material to the firm's DMS. Unsafe: bulk broadcast to non-clients, marketing template messages to purchased lists, drip campaigns, missed-call promotional flows, WhatsApp Status case-outcome content.
⚖️
BossBot product

BossBot for Law Firms & Solicitors

Product page with honest feature list, "not for you if" filter, and live demo for this vertical.

See /for/law-firm →
What a conversation looks like
🤖
BossBot AI
● Online
Hi, I need advice on a contract dispute with a supplier. They haven't paid an invoice for 3 months
Hi! We handle commercial contract disputes regularly — this sounds like something we can help with. Would you like to book a free 15-minute initial call?
Yes please. Do you work on a no-win-no-fee basis?
For debt recovery cases we do offer conditional fee arrangements. Book a call and our solicitor will assess your case. What day suits you?
Tuesday or Wednesday morning would work
Tuesday 10am is available ✅ I'll confirm your slot — can I take your name and a brief summary of the contract value?
See full demo for your business →
🏢
See it in action
BossBot for Indian law firm whatsapp automation →
Features, demo, and pricing

See how BossBot fits a compliant Indian law firm setup

Inbound-first WhatsApp Business Platform with DPDPA-ready DPA. 7-day trial, no card.

Start Free

Not ready to sign up yet? Try the free demo →

How did this land for you?
Tap what fits. Anonymous, one per browser.
✨ Recorded. Thanks for the vote.
⚖️ Law firm? Weekly notes on what other firms use. Free.